CVE-2025-20362
CVE-2025-20362
In short
A flaw in Cisco Secure Firewall (ASA and FTD) lets attackers access VPN management pages without logging in by sending specially crafted web requests. This could expose sensitive VPN information or allow unauthorized configuration changes.
Technical detail
CWE-862 authorization bypass in the VPN web server due to improper input validation in HTTP(S) requests. An unauthenticated remote attacker can craft HTTP requests to access restricted VPN endpoints that should require authentication, potentially leading to information disclosure or unauthorized configuration.
Summary generated and translated by AI from the official description.
Update: On November 5, 2025, Cisco became aware of a new attack variant against devices running Cisco Secure ASA Software or Cisco Secure FTD Software releases that are affected by CVE-2025-20333 and CVE-2025-20362. This attack can cause unpatched devices to unexpectedly reload, leading to denial of service (DoS) conditions. Cisco strongly recommends that all customers upgrade to the fixed software releases that are listed in the Fixed Software ["#fs"] section of this advisory.
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to access restricted URL endpoints that are related to remote access VPN that should otherwise be inaccessible without authentication.
This vulnerability is due to improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server on a device. A successful exploit could allow the attacker to access a restricted URL without authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
Cisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCisco · Cisco Secure Firewall Threat Defense (FTD) Softwarepublic PoCs found — 1
githubgithub.com/curtishoughton/CVE-2025-20362-Cisco-Scanner★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →